Manage access to Amazon Web Services accounts
Account access manager is integrated with IAM Identity Center and Amazon Organizations to centrally manage the assignment of existing IAM roles across multiple Amazon Web Services accounts without configuring each of your accounts individually. With account access manager, you assign existing IAM roles in your Amazon Web Services accounts to IAM Identity Center users and groups to control their access to specific Amazon Web Services accounts.
With account access manager, your teams can create their own custom IAM roles in their Amazon Web Services accounts, and you as administrator use account access manager to centrally manage assignments of IAM Identity Center users and groups to these IAM roles.
Note
Within the context of account access manager, the terms users and groups exclusively refer to workforce users and groups in IAM Identity Center.